GunSpec
Data collection

Data collection

What we collect, why, for how long and who else sees it, store by store, and what we do not do with any of it. The inventory below is the one the code is checked against; the retention figures are the ones the Privacy Policy states.

  • 13Stores
  • 8Hold personal data
  • 5Subprocessors
  • 0Models trained on your data

Stated once, in the same words the Privacy Policy carries. These are commitments, not a description of current practice that could drift.

  • We do not use your account data, API requests, support tickets, reports, webhooks or seller listings to train, fine-tune or evaluate any machine-learning model, ours or anyone else’s.
  • We do not sell, license or share your data with any AI provider for training. Where a model runs on this platform it reads public web pages and our own catalog, never data you sent us.
  • We do not build behavioural profiles. Usage is counted per key for the allowance; nothing infers what you are building from what you request.
  • The catalog you receive is ours to publish and yours to use under your plan. What you do with it, including training your own models on it where your plan permits, is not reported back to us.

Every store, grouped by the surface that fills it, with its fields named as the code names them. ip_address in a store means the address is kept as sent, for the period shown, and then deleted with the row.

RowDataFieldsRetentionProcessorsPersonal
The website and your account
01AccountTo run the account: sign-in, the plan, billing state and which emails you have asked for.email, display_name, tier, notification_prefs, created_at30 daysCloudflare, Stripe, ResendYes
02API keysTo authenticate API calls. The key itself is shown once and stored only as a hash.key_hash, name, tier, enabled, expires_at, last_used_atWhile the account existsCloudflareNo
03Website sessionsTo keep you signed in on the website and let you see and revoke your own sessions.token_hash, ip_address, user_agent, device_label, last_active_at, expires_atUntil sign-out or expiryCloudflareYes
04Sign-in historyTo show you your sign-in history and to notice a credential being attacked.email, ip_address, user_agent, success, failure_reason, created_at30 daysCloudflareYes
05BillingTo bill the plan. Card numbers never reach us; Stripe holds them and we keep only its identifiers and the invoice record tax law requires.stripe_customer_id, subscription_status, invoices7 yearsCloudflare, StripeYes
06Website analyticsTo see which pages are used, in aggregate. Loads only after you accept analytics in the cookie banner; denied by default.page_views, aggregate_eventsNever kept by usGoogle AnalyticsNo
07Website error reportsTo find a crash in the website before you report it. The website only; the API never reports to it.stack_trace, page_url, browser, ip_address90 daysSentryYes
The API
08API request logsRate limiting, abuse detection, the usage meter, debugging a request you report by its id. Query strings and bodies are not logged; response bodies are never logged.request_id, method, path, status_code, duration_ms, api_key_id, user_id, tier, error_code, user_agent, ip_address, country_code, response_size90 daysCloudflareYes
09Usage countersThe monthly allowance and the daily cap. A count per key per day, nothing about the requests themselves.api_key_id, date, request_countWhile the account existsCloudflareNo
10Support tickets and data reportsTo answer a ticket or act on a data-correction report. Attachments are private to the ticket and its owner.subject, description, category, attachments, data_report_fieldsWhile the account existsCloudflareYes
11Webhook endpointsTo deliver catalog changes to an endpoint you registered, and to show you whether each delivery succeeded.endpoint_url, events, signing_secret_hash, delivery_logWhile the account existsCloudflareNo
12Seller listingsTo list a shop and its offers, and to report the traffic those listings receive. Counts are per listing per day, never per visitor.shop_name, website, contact_email, offers, click_countsWhile the account existsCloudflareYes
This documentation
13Browser storageConveniences that live in your browser: the theme, the pages you opened, the key you pasted into the Try It console and its request history. None of it is sent to us.theme, recently_viewed, playground_api_key, playground_history, cookie_choicesNever kept by usOnly usNo

Retention periods are the ones the Privacy Policy states. Processors are the subprocessors that hold or transmit the store; every server-side store is hosted on Cloudflare.

A model runs in 2 places on this platform. Each is listed with what it reads. Neither reads anything you sent us.

  • Industry news triage

    Sorts harvested industry news into announcements and everything else.

    Reads
    Public RSS and Atom articles we fetched.
    Provider
    Workers AI
  • Specification extraction

    Reads a manufacturer page and reports what it states for a field, for the accuracy benchmark.

    Reads
    Public manufacturer pages and our own catalog record.
    Provider
    OpenRouter

The reverse direction is documented on the AI & LLMs page: how to hand the API to your own model. That is your data flowing to your model, on your terms, and nothing about it flows back to us beyond the request counts every call produces.

The subprocessors any store above names, with the stores that reach them. A provider not on this list never receives your data.

ProviderRoleRegionStores
Cloudflarehosting, edge compute, database, object storage, securityUS and globalAccount, API keys, API request logs, Usage counters, Website sessions, Sign-in history, Billing, Support tickets and data reports, Webhook endpoints, Seller listings
Stripepayments and subscription billing; card details never touch usUS and IrelandAccount, Billing
Google Analyticsopt-in analytics, loaded only after consentUSWebsite analytics
Resendlogin codes and account emailUSAccount
Sentryerror reports from the website only; the API never reports to itUSWebsite error reports

The full subprocessor list, the transfer mechanism and the breach-notification commitment are on the data protections page.

Access, correction, deletion, portability and objection, under the GDPR and the Australian Privacy Principles. Most of it you can do yourself; the rest is one email to legal@buungroup.com.

  1. 01Export everything we hold on you from your profile: the account record, its sessions and sign-in history, as JSON.
  2. 02Delete the account from the same page. Personal data goes within the deletion window above; billing records stay for the period tax law requires, and nothing else survives.
  3. 03Revoke a session, rotate a key or disable one at any time. A revoked key stops working on the next request.
  4. 04Turn analytics off in the cookie banner at any time. It was off until you turned it on.
  5. 05Ask for anything else, or lodge a complaint, at legal@buungroup.com. Australian users may also contact the OAIC, and EEA users their local authority.